2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41988 | HIGH | 7.5 | 1.2% | Dec 22, 2022 | An information disclosure vulnerability exists in the OpenImageIO::decode_iptc_iim() functionality of OpenImageIO Projec... |
| CVE-2022-41981 | HIGH | 8.1 | 1.0% | Dec 22, 2022 | A stack-based buffer overflow vulnerability exists in the TGA file format parser of OpenImageIO v2.3.19.0. A specially-c... |
| CVE-2022-22184 | HIGH | 7.5 | 0.7% | Dec 22, 2022 | An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos O... |
| CVE-2022-3805 | HIGH | 7.5 | 1.6% | Dec 22, 2022 | The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the... |
| CVE-2022-46885 | HIGH | 8.8 | 0.5% | Dec 22, 2022 | Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Fire... |
| CVE-2022-46883 | HIGH | 8.8 | 0.6% | Dec 22, 2022 | Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety... |
| CVE-2022-46881 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploita... |
| CVE-2022-46879 | HIGH | 8.8 | 0.6% | Dec 22, 2022 | Mozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Mozilla Fuzzing Team re... |
| CVE-2022-46878 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs p... |
| CVE-2022-46874 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious ext... |
| CVE-2022-46873 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject marku... |
| CVE-2022-46872 | HIGH | 8.6 | 0.8% | Dec 22, 2022 | An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipb... |
| CVE-2022-46871 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability af... |
| CVE-2022-45421 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some o... |
| CVE-2022-45415 | HIGH | 7.8 | 0.2% | Dec 22, 2022 | When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox ... |
| CVE-2022-45414 | HIGH | 8.1 | 0.5% | Dec 22, 2022 | If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a ... |
| CVE-2022-45412 | HIGH | 8.8 | 0.8% | Dec 22, 2022 | When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink... |
| CVE-2022-45409 | HIGH | 8.8 | 0.8% | Dec 22, 2022 | The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> m... |
| CVE-2022-45407 | HIGH | 7.5 | 0.6% | Dec 22, 2022 | If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred,... |
| CVE-2022-42932 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firef... |
| CVE-2022-42930 | HIGH | 7.1 | 0.4% | Dec 22, 2022 | If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUt... |
| CVE-2022-42928 | HIGH | 8.8 | 0.8% | Dec 22, 2022 | Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have... |
| CVE-2022-42927 | HIGH | 8.1 | 0.4% | Dec 22, 2022 | A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirec... |
| CVE-2022-40962 | HIGH | 8.8 | 1.3% | Dec 22, 2022 | Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reporte... |
| CVE-2022-3155 | HIGH | 7.8 | 0.2% | Dec 22, 2022 | When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the recei... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now